Live data from Hacker News

Viewing profile — ericselin

ericselin

HN member
Joined
Mon, Nov 15, 2021, 11:09 AM UTC
HN karma
131
Public activity
28 items

About ericselin

No profile information was provided.

Recent public activity

  1. comment
    Comment #46616951

    FreeSwewing is an awesome project by Joost De Cock! You should totally check it out if you're into sewing. And if you're into digital sovereignty tou should totally check out stati…

  2. story
  3. comment
    Comment #45544783

    Based on what I've seen, there's no way to get that project into the PSL. I would recommend you to have the content available at projectcontent.com if the main site is project.com,…

  4. comment
    Comment #45544561

    The thing is, for users, having a separate domain wouldn't have made any difference without the PSL. And you cannot get on there before you're big enough - which I'd say is roughly…

  5. comment
    Comment #45544514

    Sure, and sorry for being so unclear. The point of my post was meant to be a) Google has this enormous cannon, is this "right"? And b) they will use it to kill anything bigger than…

  6. comment
    Comment #45544463

    Ok, I see. You mean the possibility of users impersonating statichost.eu itself. That is actually a good point, and the exact reason why user subdomains are required to have a dash…

  7. comment
    Comment #45544385

    Author here. What kind of security negligence are you referring to? What would be a specific attack vector that I left open? Regarding the PSL - and I can't believe I'm writing thi…

  8. comment
    Comment #45543772

    Thank you for this hacker-minded and sharp comment! And for what it's worth, it feels great to actually pay for something Google provides!

  9. comment
    Comment #45543658

    Many commenters are implying that there is a security issue here, and that I'm putting everyone in danger. That is quite frankly a pretty absurd claim to just casually make. I'm of…

  10. comment
    Comment #45542960

    Author here. I understand that my post and what I'm trying to say is unclear. And that there are too many different aspects to all this. What I'm trying to say in the post specific…

  11. comment
    Comment #45542121

    So the problem here is that Alice on alice.statichost.page might set a cookie for the `.statichost.page` domain if she's careless (which is sometimes the case with Alice). This coo…

  12. comment
    Comment #45540753

    https://github.com/publicsuffix/list/wiki/Guidelines#validat... "Projects that are smaller in scale or are temporary or seasonal in nature will likely be declined. Examples of this…

  13. comment
    Comment #45540230

    Please note that this tool (PSL) is not available until you have a significant user base. Which probably means a significant amount of spam as well.

  14. comment
    Comment #45540178

    Fair enough! :)

  15. comment
    Comment #45540096

    Since there's a lot of discussion about the Public Suffix list, let me point out that it's not just a webform where you can add any domain. There's a whole approval process where o…

  16. comment
    Comment #45539680

    The thing is, you cannot just add any domain to the PSL. You need a significant amount of users before they will include your domain. Before recently, there really was no point in …

  17. comment
    Comment #45539454

    I respectfully disagree with your premise. In this specific case, yes, "Google does good thing" in a sense. That is not why I'm saying Google has too much power. "Too much" is rela…

  18. comment
    Comment #45539351

    You are right, it would still affect all users. Until the pending PSL inclusion is complete, that is. But it now separates my own resources, such as the website and dashboard of st…

  19. comment
    Comment #45539250

    (Author here) This is all true. The main assumption from my part is that anything remotely important or even sensitive should be and is hosted on a domain that is _not_ companysubd…

  20. comment
    Comment #45539188

    That is a great point. When I see these sites I'm always seeing a dozen red flags, and maybe the biggest one is that it's showing a "NatWest" banking site or something and is hoste…

  21. comment
    Comment #45539144

    You are right, of course. I'm not sure if those of you who disagree with me think that Safe Browsing did its job (which it did!), that Safe Browsing is a good thing (which it maybe…

  22. comment
    Comment #45539070

    I'm not saying that Google or Safe Browsing in particular did anything wrong per se. My point is primarily that Google has too much power over the internet. I know that in this cas…

  23. comment
    Comment #45538981

    This is of course true! It just takes an incident like this to get ones head out of ones ass and actually do it. :)

  24. comment
    Comment #45538874

    Good question, it probably shouldn't be legal. Enforcing the law on these behemoths is another problem, though... :)

  25. story